Skip to main content

Security and confidentiality

Protecting company, employee, customer, and partner information is part of earning peace of mind.

  • Use approved accounts, devices, services, and access methods for company work.
  • Request only the access needed for your responsibilities and never share credentials.
  • Store and share information only in approved locations and with intended recipients.
  • Verify unusual requests involving credentials, payments, personal data, or access.
  • Keep important actions traceable and reversible when the system allows it.
  • Report suspected loss, exposure, phishing, unauthorized access, or device compromise immediately through the designated security channel.
  • Return company information, equipment, and access when responsibilities change.

Do not publish, forward, or use confidential information for a purpose that has not been approved. When classification or handling requirements are unclear, pause and ask the appropriate owner.

:::caution Policy details pending Security must add approved tools, data classifications, retention requirements, incident contacts, and role-specific controls before this page is complete. :::


Guidance type: Policy framework
Owner: Security